CVE Database

53300+ vulnerabilities with CVSS scores, EPSS exploit predictions, and CISA KEV status. Updated daily.

Filter: All CRITICAL HIGH MEDIUM LOW CISA KEV
Sort: Newest CVSS EPSS
CVE-2024-49794
4.3 MEDIUM

IBM ApplinX 11.1 is vulnerable to cross-site request forgery which could allow an attacker to execute malicious and unauthorized actions transmitted from a user that …

Feb 6, 2025
CVE-2024-49793
5.4 MEDIUM

IBM ApplinX 11.1 is vulnerable to cross-site scripting. This vulnerability allows an authenticated user to embed arbitrary JavaScript code in the Web UI thus altering …

Feb 6, 2025
CVE-2024-49792
5.4 MEDIUM

IBM ApplinX 11.1 is vulnerable to cross-site scripting. This vulnerability allows an authenticated user to embed arbitrary JavaScript code in the Web UI thus altering …

Feb 6, 2025
CVE-2024-49791
6.4 MEDIUM

IBM ApplinX 11.1 is vulnerable to cross-site scripting. This vulnerability allows an authenticated user to embed arbitrary JavaScript code in the Web UI thus altering …

Feb 6, 2025
CVE-2024-56473
5.3 MEDIUM

IBM Aspera Shares 1.9.0 through 1.10.0 PL6 could allow an attacker to spoof their IP address, which is written to log files, due to improper …

Feb 5, 2025
CVE-2024-56472
6.4 MEDIUM

IBM Aspera Shares 1.9.0 through 1.10.0 PL6 is vulnerable to stored cross-site scripting. This vulnerability allows authenticated users to embed arbitrary JavaScript code in the …

Feb 5, 2025
CVE-2024-56471
5.4 MEDIUM

IBM Aspera Shares 1.9.0 through 1.10.0 PL6 is vulnerable to server-side request forgery (SSRF). This may allow an authenticated attacker to send unauthorized requests from …

Feb 5, 2025
CVE-2024-56470
5.4 MEDIUM

IBM Aspera Shares 1.9.0 through 1.10.0 PL6 is vulnerable to server-side request forgery (SSRF). This may allow an authenticated attacker to send unauthorized requests from …

Feb 5, 2025
CVE-2024-38318
4.8 MEDIUM

IBM Aspera Shares 1.9.0 through 1.10.0 PL6 is vulnerable to HTML injection. A remote attacker could inject malicious HTML code, which when viewed, would be …

Feb 5, 2025
CVE-2024-38317
4.8 MEDIUM

IBM Aspera Shares 1.9.0 through 1.10.0 PL6 is vulnerable to cross-site scripting. This vulnerability allows a privileged user to embed arbitrary JavaScript code in the …

Feb 5, 2025
CVE-2024-38316
4.3 MEDIUM

IBM Aspera Shares 1.9.0 through 1.10.0 PL6 does not properly rate limit the frequency that an authenticated user can send emails, which could result in …

Feb 5, 2025
CVE-2024-57598
6.5 MEDIUM

A floating point exception (divide-by-zero) vulnerability was discovered in Bento4 1.6.0-641 in function AP4_TfraAtom() of Ap4TfraAtom.cpp which allows a remote attacker to cause a denial …

Feb 5, 2025
CVE-2024-57082
6.5 MEDIUM

A prototype pollution in the lib.createUploader function of @rpldy/uploader v1.8.1 allows attackers to cause a Denial of Service (DoS) via supplying a crafted payload.

Feb 5, 2025
CVE-2024-54853
5.4 MEDIUM

A Stored Cross-Site Scripting (XSS) vulnerability was identified affecting Skybox Change Manager versions 13.2.170 and earlier that allows remote authenticated users to store malicious payloads …

Feb 5, 2025
CVE-2025-24805
5.5 MEDIUM

Mobile Security Framework (MobSF) is an automated, all-in-one mobile application (Android/iOS/Windows) pen-testing, malware analysis and security assessment framework. A local user with minimal privileges is …

Feb 5, 2025
CVE-2025-24804
4.3 MEDIUM

Mobile Security Framework (MobSF) is an automated, all-in-one mobile application (Android/iOS/Windows) pen-testing, malware analysis and security assessment framework. According to Apple's documentation for bundle ID's, …

Feb 5, 2025
CVE-2025-24803
5.4 MEDIUM

Mobile Security Framework (MobSF) is an automated, all-in-one mobile application (Android/iOS/Windows) pen-testing, malware analysis and security assessment framework. According to Apple's documentation for bundle ID's, …

Feb 5, 2025
CVE-2025-24319
6.5 MEDIUM

When BIG-IP Next Central Manager is running, undisclosed requests to the BIG-IP Next Central Manager API can cause the BIG-IP Next Central Manager Node's Kubernetes …

Feb 5, 2025
CVE-2025-23419
4.3 MEDIUM

When multiple server blocks are configured to share the same IP address and port, an attacker can use session resumption to bypass client certificate authentication …

Feb 5, 2025
CVE-2025-23413
4.4 MEDIUM

When users log in through the webUI or API using local authentication, BIG-IP Next Central Manager may log sensitive information in the pgaudit log files. …

Feb 5, 2025
CVE-2024-7596
6.5 MEDIUM

Proposed Generic UDP Encapsulation (GUE) (IETF Draft) do not validate or verify the source of a network packet allowing an attacker to spoof and route …

Feb 5, 2025
CVE-2024-7595
6.5 MEDIUM

GRE and GRE6 Protocols (RFC2784) do not validate or verify the source of a network packet allowing an attacker to spoof and route arbitrary traffic …

Feb 5, 2025
CVE-2025-20207
4.3 MEDIUM

A vulnerability in Simple Network Management Protocol (SNMP) polling for Cisco Secure Email and Web Manager, Cisco Secure Email Gateway, and Cisco Secure Web Appliance …

Feb 5, 2025
CVE-2025-20205
4.8 MEDIUM

Multiple vulnerabilities in the web-based management interface of Cisco Identity Services Engine (ISE) could allow an authenticated, remote attacker to conduct cross-site scripting (XSS) attacks …

Feb 5, 2025
CVE-2025-20204
4.8 MEDIUM

Multiple vulnerabilities in the web-based management interface of Cisco Identity Services Engine (ISE) could allow an authenticated, remote attacker to conduct cross-site scripting (XSS) attacks …

Feb 5, 2025
CVE-2025-20184
6.5 MEDIUM

A vulnerability in the web-based management interface of Cisco AsyncOS Software for Cisco Secure Email Gateway and Cisco Secure Web Appliance could allow an authenticated, …

Feb 5, 2025
CVE-2025-20183
5.8 MEDIUM

A vulnerability in a policy-based Cisco Application Visibility and Control (AVC) implementation of Cisco AsyncOS Software for Cisco Secure Web Appliance could allow an unauthenticated, …

Feb 5, 2025
CVE-2025-20180
4.8 MEDIUM

A vulnerability in the web-based management interface of Cisco AsyncOS Software for Cisco Secure Email and Web Manager and Secure Email Gateway could allow an …

Feb 5, 2025
CVE-2025-20179
6.1 MEDIUM

A vulnerability in the web-based management interface of Cisco Expressway Series could allow an unauthenticated, remote attacker to conduct a cross-site scripting (XSS) attack against …

Feb 5, 2025
CVE-2024-42207
5.5 MEDIUM

HCL iAutomate is affected by a session fixation vulnerability. An attacker could hijack a victim's session ID from their authenticated session.

Feb 5, 2025
CVE-2025-21117
6.6 MEDIUM

Dell Avamar, version 19.4 or later, contains an access token reuse vulnerability in the AUI. A low privileged local attacker could potentially exploit this vulnerability, …

Feb 5, 2025
CVE-2024-52365
6.4 MEDIUM

IBM Cloud Pak for Business Automation 18.0.0, 18.0.1, 18.0.2, 19.0.1, 19.0.2, 19.0.3, 20.0.1, 20.0.2, 20.0.3, 21.0.1, 21.0.2, 21.0.3, 22.0.1, and 22.0.2 is vulnerable to stored …

Feb 5, 2025
CVE-2024-52364
5.4 MEDIUM

IBM Cloud Pak for Business Automation 18.0.0, 18.0.1, 18.0.2, 19.0.1, 19.0.2, 19.0.3, 20.0.1, 20.0.2, 20.0.3, 21.0.1, 21.0.2, 21.0.3, 22.0.1, and 22.0.2 is vulnerable to cross-site …

Feb 5, 2025
CVE-2024-49348
4.3 MEDIUM

IBM Cloud Pak for Business Automation 18.0.0, 18.0.1, 18.0.2, 19.0.1, 19.0.2, 19.0.3, 20.0.1, 20.0.2, 20.0.3, 21.0.1, 21.0.2, 21.0.3, 22.0.1, and 22.0.2 allows restricting access to …

Feb 5, 2025
CVE-2024-3976
6.5 MEDIUM

An issue has been discovered in GitLab CE/EE affecting all versions starting from 14.0 prior to 16.9.7, starting from 16.10 prior to 16.10.5, and starting …

Feb 5, 2025
CVE-2024-6356
4.4 MEDIUM

An issue was discovered in GitLab EE affecting all versions starting from 16.0 prior to 17.0.6, starting from 17.1 prior to 17.1.4, and starting from …

Feb 5, 2025
CVE-2024-1539
4.3 MEDIUM

An issue has been discovered in GitLab EE affecting all versions starting from 15.2 prior to 16.9.7, starting from 16.10 prior to 16.10.5, and starting …

Feb 5, 2025
CVE-2023-6386
6.5 MEDIUM

A denial of service vulnerability was identified in GitLab CE/EE, affecting all versions from 15.11 prior to 16.6.7, 16.7 prior to 16.7.5 and 16.8 prior …

Feb 5, 2025
CVE-2023-52925
5.5 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: netfilter: nf_tables: don't fail inserts if duplicate has expired nftables selftests fail: run-tests.sh testcases/sets/0044interval_overlap_0 Expected: …

Feb 5, 2025
CVE-2023-52924
5.5 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: netfilter: nf_tables: don't skip expired elements during walk There is an asymmetry between commit/abort and …

Feb 5, 2025
CVE-2024-13829
5.3 MEDIUM

The WordPress form builder plugin for contact forms, surveys and quizzes – Tripetto plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions …

Feb 5, 2025
CVE-2024-53966
5.4 MEDIUM

Adobe Experience Manager versions 6.5.21 and earlier are affected by a stored Cross-Site Scripting (XSS) vulnerability that could be abused by a low privileged attacker …

Feb 5, 2025
CVE-2024-53965
5.4 MEDIUM

Adobe Experience Manager versions 6.5.21 and earlier are affected by a DOM-based Cross-Site Scripting (XSS) vulnerability that could be exploited by a low privileged attacker …

Feb 5, 2025
CVE-2024-53964
5.4 MEDIUM

Adobe Experience Manager versions 6.5.21 and earlier are affected by a stored Cross-Site Scripting (XSS) vulnerability that could be abused by a low privileged attacker …

Feb 5, 2025
CVE-2024-53963
5.4 MEDIUM

Adobe Experience Manager versions 6.5.21 and earlier are affected by a DOM-based Cross-Site Scripting (XSS) vulnerability that could be exploited by a low privileged attacker …

Feb 5, 2025
CVE-2024-53962
5.4 MEDIUM

Adobe Experience Manager versions 6.5.21 and earlier are affected by a stored Cross-Site Scripting (XSS) vulnerability that could be abused by a low privileged attacker …

Feb 5, 2025
CVE-2024-53994
4.3 MEDIUM

Discourse is an open source platform for community discussion. In affected versions users who disable chat in preferences could still be reachable in some cases. …

Feb 4, 2025
CVE-2024-53851
4.3 MEDIUM

Discourse is an open source platform for community discussion. In affected versions the endpoint for generating inline oneboxes for URLs wasn't enforcing limits on the …

Feb 4, 2025
CVE-2024-53266
4.3 MEDIUM

Discourse is an open source platform for community discussion. In affected versions with some combinations of plugins, and with CSP disabled, activity streams in the …

Feb 4, 2025
CVE-2024-13722
5.4 MEDIUM

The "NagVis" component within Checkmk is vulnerable to reflected cross-site scripting. An attacker can craft a malicious link that will execute arbitrary JavaScript in the …

Feb 4, 2025

Scan your infrastructure for known CVEs

Free website and port scanning — find vulnerabilities before attackers do.